Third Party Certificates for Secure Endpoint Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device management systems face challenges in establishing authority over endpoint devices during onboarding, particularly when orchestrators lack access to private keys, leading to potential security compromises and limitations in key proliferation.

Innovation Solution

The use of third party certificates to extend delegation chains in ownership vouchers, allowing endpoint devices to validate authority delegation to orchestrators without requiring access to private keys, thereby reducing key proliferation and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If orchestrators are given access to private keys for device management, then device management capability is improved, but security risk increases due to key proliferation

Engineering Contradiction:
Improvedevice management capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a delegation certificate as an intermediary mechanism that enables orchestrators to manage devices without directly accessing private keys. The certificate acts as a mediator that proves authority delegation from the device owner to the orchestrator, allowing management operations while maintaining cryptographic security by keeping private keys confined to their intended holders.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If private keys are distributed to multiple orchestrators for device onboarding, then device management flexibility is improved, but key security is compromised due to widespread distribution

Engineering Contradiction:
Improvedevice management flexibilityVSAvoidkey security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the authority management into two distinct components: private key custody (held securely by device owners) and management authority (delegated via certificates to orchestrators). This segmentation allows multiple orchestrators to be granted management flexibility through individual delegation certificates without requiring widespread private key distribution, thus maintaining key security while achieving operational versatility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Delegation certificates serve as intermediaries that enable flexible orchestrator management without compromising key security. Each orchestrator receives a certificate that mediates their authority to manage specific devices, allowing the system to adapt to various management scenarios while keeping private keys securely confined to their original holders.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If orchestrators validate authority through direct private key access, then onboarding speed is improved, but security exposure increases

Engineering Contradiction:
Improveonboarding speedVSAvoidsecurity exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The delegation certificate acts as a fast-validating intermediary that enables orchestrators to prove their authority without accessing private keys. The certificate contains cryptographic proofs that can be rapidly verified by devices during onboarding, maintaining high onboarding speed while eliminating the security exposure that would result from orchestrator access to private keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250184136A1Methods for secure onboarding and management by third parties
Publication Date: 2025.06.05 DELL PROD LP
  • US20250184136A1 patent drawing
  • US20250184136A1 patent drawing
  • US20250184136A1 patent drawing

AI summary

Methods and systems for managing endpoint devices are disclosed. The endpoint devices may be managed by onboarding them. To onboarding the endpoint devices, ownership vouchers and third party certificates may be used to cryptographically verify to which entities authority over the endpoint devices have been delegated. The third party certificates may extend certificate and/or delegation chains in ownership vouchers to other devices. The extended chains may eliminate the need for proliferation of keys used to demonstrate authority over endpoint devices.